Tools
The four built-in tools the agent uses.
Four built-in tools. Zero ceremony. The minimum viable toolbox for an agent that actually ships code.
Jail mode
Type /jail to confine every tool to the current directory. Bash refuses sudo, rm -rf /, and other obvious escape patterns. It is a guardrail against accidents, not a hard security boundary. See Jail mode for the full behavior.